composer/composer · error · RuntimeException

Advisory for could not be loaded as a full advisory from

Error message

Advisory for ${name} could not be loaded as a full advisory from ${getRepoName()}
${var_export($data, true)}

What it means

Thrown inside the advisory-creation closure during security advisory fetching when a remote advisory cannot be hydrated into a full SecurityAdvisory and partial advisories are not allowed. The data dump is included to aid diagnosis. This signals the upstream repository returned incomplete or malformed advisory data.

Solutions

  1. Inspect the var_export dump in the error to see which fields are missing.
  2. If you control the advisory feed, ensure it returns all fields required for a full SecurityAdvisory.
  3. If you cannot fix the feed, allow partial advisories via the appropriate audit option/config so the loader degrades gracefully.
  4. Verify you are running a Composer version compatible with the feed's advisory schema.
Defensive patterns

Strategy: try-catch

Try / catch

try {
    $advisories = $repo->getSecurityAdvisories($packages, false);
} catch (\RuntimeException $e) {
    if (str_contains($e->getMessage(), 'could not be loaded as a full advisory')) { /* retry with allowPartialAdvisories=true, or report upstream */ }
    else { throw $e; }
}

Prevention

When it happens

Trigger: When $allowPartialAdvisories is false (the caller requires full advisories) and PartialSecurityAdvisory::create returns only a PartialSecurityAdvisory (missing required fields like patches, sources, or proper linking). The check at line 726 triggers.

Common situations: A custom/private packagist-like server returning advisory payloads missing required fields. Composer run with strict advisory settings against a repo whose advisory schema is incomplete. Version skew between Composer and the advisory feed.

Related errors


AI-assisted analysis of composer/composer@c435d285c9 (2026-08-07). Data as JSON: /api/errors/9134904a56288e18. Report an issue: GitHub.

Appendix: source

Thrown at src/Composer/Repository/ComposerRepository.php:727

        // respect available-package-patterns / available-packages directives from the repo
        if ($this->hasAvailablePackageList) {
            foreach ($packageConstraintMap as $name => $constraint) {
                if (!$this->lazyProvidersRepoContains(strtolower($name))) {
                    unset($packageConstraintMap[$name]);
                }
            }
        }

        $parser = new VersionParser();
        /**
         * @param array<mixed> $data
         * @param string $name
         * @return ($allowPartialAdvisories is false ? SecurityAdvisory|null : PartialSecurityAdvisory|SecurityAdvisory|null)
         */
        $create = function (array $data, string $name) use ($parser, $allowPartialAdvisories, &$packageConstraintMap): ?PartialSecurityAdvisory {
            $advisory = PartialSecurityAdvisory::create($name, $data, $parser);
            if (!$allowPartialAdvisories && !$advisory instanceof SecurityAdvisory) {
                throw new \RuntimeException('Advisory for '.$name.' could not be loaded as a full advisory from '.$this->getRepoName() . PHP_EOL . var_export($data, true));
            }
            if (!$advisory->affectedVersions->matches($packageConstraintMap[$name])) {
                return null;
            }

            return $advisory;
        };

        if ($this->securityAdvisoryConfig['metadata'] && ($allowPartialAdvisories || $apiUrl === null)) {
            $promises = [];
            foreach ($packageConstraintMap as $name => $constraint) {
                $name = strtolower($name);

                // skip platform packages, root package and composer-plugin-api
                if (PlatformRepository::isPlatformPackage($name) || '__root__' === $name) {
                    continue;
                }

View on GitHub (pinned to c435d285c9)